Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sushant Vitthal Kamble

#43393of 53,633
6.1Total CVSS
Vulnerabilities · 1
PT-2021-21272
6.1
2021-12-15
Verint · Verint Workforce Optimization · CVE-2021-36450
**Name of the Vulnerable Software and Affected Versions** Verint Workforce Optimization (WFO) version 15.2.8.10048 **Description** The issue allows for cross-site scripting (XSS) attacks. This is possible due to the `NEWUINAV` parameter in the "control/my notifications" API endpoint. **Recommendations** For version 15.2.8.10048, avoid using the `NEWUINAV` parameter in the "control/my notifications" API endpoint until the issue is resolved.